CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-1155
4.3 MEDIUM

A vulnerability, which was classified as problematic, was found in Webkul QloApps 1.6.1. This affects an unknown part of the file /stores of the component …

Feb 10, 2025
CVE-2025-1154
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in xxyopen Novel up to 3.4.1. Affected by this issue is some unknown functionality of …

Feb 10, 2025
CVE-2024-57178
5.9 MEDIUM

An SQL injection vulnerability exists in Stock-Forecaster <=01-04-2020. By sending a specially crafted 'stock-symbol' parameter to the portofolio() endpoint, it is possible to trigger an …

Feb 10, 2025
CVE-2024-57177
7.3 HIGH

A host header injection vulnerability exists in the NPM package of perfood/couch-auth <= 0.21.2. By sending a specially crafted host header in the email change …

Feb 10, 2025
CVE-2025-24200
6.1 MEDIUM KEV

An authorization issue was addressed with improved state management. This issue is fixed in iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS 16.7.11, iOS …

Feb 10, 2025
CVE-2025-1153
3.1 LOW

A vulnerability classified as problematic was found in GNU Binutils 2.43/2.44. Affected by this vulnerability is the function bfd_set_format of the file format.c. The manipulation …

Feb 10, 2025
CVE-2024-8550
7.5 HIGH

A Local File Inclusion (LFI) vulnerability exists in the /load-workflow endpoint of modelscope/agentscope version v0.0.4. This vulnerability allows an attacker to read arbitrary files from …

Feb 10, 2025
CVE-2024-54658
6.5 MEDIUM

The issue was addressed with improved memory handling. This issue is fixed in Safari 17.4, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, …

Feb 10, 2025
CVE-2024-46437
6.5 MEDIUM

A sensitive information disclosure vulnerability in the Tenda W18E V16.01.0.8(1625) web management portal allows an unauthenticated remote attacker to retrieve sensitive configuration information, including WiFi …

Feb 10, 2025
CVE-2024-46436
8.3 HIGH

Hardcoded credentials in Tenda W18E V16.01.0.8(1625) allows unauthenticated remote attackers to gain root access to the device over the telnet service.

Feb 10, 2025
CVE-2024-46435
8.0 HIGH

A stack overflow vulnerability in the Tenda W18E V16.01.0.8(1625) web management portal allows an authenticated remote attacker to cause a denial of service or potentially …

Feb 10, 2025
CVE-2024-46434
8.8 HIGH

Tenda W18E V16.01.0.8(1625) suffers from authentication bypass in the web management portal allowing an unauthorized remote attacker to gain administrative access by sending a specially …

Feb 10, 2025
CVE-2024-46433
8.8 HIGH

A default credentials vulnerability in Tenda W18E V16.01.0.8(1625) allows unauthenticated remote attackers to access the web management portal using the default rzadmin account with administrative …

Feb 10, 2025
CVE-2024-46432
8.8 HIGH

Tenda W18E V16.01.0.8(1625) is vulnerable to Incorrect Access Control. An attacker can send a specially crafted HTTP POST request to the setQuickCfgWifiAndLogin function, which allows …

Feb 10, 2025
CVE-2024-46431
8.0 HIGH

Tenda W18E V16.01.0.8(1625) is vulnerable to Buffer Overflow. An attacker with access to the web management portal can exploit this vulnerability by sending specially crafted …

Feb 10, 2025
CVE-2024-46430
6.5 MEDIUM

Tenda W18E V16.01.0.8(1625) is vulnerable to Incorrect Access Control. Unauthorized password change via the web management portal allows an unauthenticated remote attacker to change the …

Feb 10, 2025
CVE-2024-46429
8.8 HIGH

A hardcoded credentials vulnerability in Tenda W18E V16.01.0.8(1625) allows unauthenticated remote attackers to access the web management portal using a default guest account with administrative …

Feb 10, 2025
CVE-2024-42513
5.3 MEDIUM

Vulnerability in the OPC UA .NET Standard Stack before 1.5.374.158 allows an unauthorized attacker to bypass application authentication when using HTTPS endpoints.

Feb 10, 2025
CVE-2024-42512
8.6 HIGH

Vulnerability in the OPC UA .NET Standard Stack before 1.5.374.158 allows an unauthorized attacker to bypass application authentication when the deprecated Basic128Rsa15 security policy is …

Feb 10, 2025
CVE-2024-27859
8.8 HIGH

The issue was addressed with improved memory handling. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, visionOS 1.1, …

Feb 10, 2025
CVE-2024-13059
7.2 HIGH

A vulnerability in mintplex-labs/anything-llm prior to version 1.3.1 allows for path traversal due to improper handling of non-ASCII filenames in the multer library. This vulnerability …

Feb 10, 2025
CVE-2024-13011
9.8 CRITICAL

The WP Foodbakery plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'upload_publisher_profile_image' function in versions up …

Feb 10, 2025
CVE-2024-13010
6.1 MEDIUM

The WP Foodbakery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4.8 due to insufficient input sanitization and …

Feb 10, 2025
CVE-2024-10649
6.1 MEDIUM

wandb/openui latest commit c945bb859979659add5f490a874140ad17c56a5d contains a vulnerability where unauthenticated endpoints allow file uploads and downloads from an AWS S3 bucket. This can lead to multiple …

Feb 10, 2025
CVE-2025-25188

Hickory DNS is a Rust based DNS client, server, and resolver. A vulnerability present starting in version 0.8.0 and prior to versions 0.24.3 and 0.25.0-alpha.5 …

Feb 10, 2025
CVE-2025-1152
3.1 LOW

A vulnerability classified as problematic has been found in GNU Binutils 2.43. Affected is the function xstrdup of the file xstrdup.c of the component ld. …

Feb 10, 2025
CVE-2024-57409
4.8 MEDIUM

A stored cross-site scripting (XSS) vulnerability in the Parameter List module of cool-admin-java v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting …

Feb 10, 2025
CVE-2024-57408
7.2 HIGH

An arbitrary file upload vulnerability in the component /comm/upload of cool-admin-java v1.0 allows attackers to execute arbitrary code via uploading a crafted file.

Feb 10, 2025
CVE-2024-57407
7.3 HIGH

An arbitrary file upload vulnerability in the component /userPicture of Timo v2.0.3 allows attackers to execute arbitrary code via uploading a crafted file.

Feb 10, 2025
CVE-2024-54954
8.0 HIGH

OneBlog v2.3.6 was discovered to contain a template injection vulnerability via the template management department.

Feb 10, 2025
CVE-2024-48170
5.4 MEDIUM

PHPGurukul Small CRM 3.0 is vulnerable to Cross Site Scripting (XSS) via a crafted payload injected into the name in the profile.php.

Feb 10, 2025
CVE-2025-1151
3.1 LOW

A vulnerability was found in GNU Binutils 2.43. It has been rated as problematic. This issue affects the function xmemdup of the file xmemdup.c of …

Feb 10, 2025
CVE-2025-1150
3.1 LOW

A vulnerability was found in GNU Binutils 2.43. It has been declared as problematic. This vulnerability affects the function bfd_malloc of the file libbfd.c of …

Feb 10, 2025
CVE-2025-25186
6.5 MEDIUM

Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Starting in version 0.3.2 and prior to versions 0.3.8, 0.4.19, and 0.5.6, there is …

Feb 10, 2025
CVE-2025-24892
3.5 LOW

OpenProject is open-source, web-based project management software. In versions prior to 15.2.1, the application fails to properly sanitize user input before displaying it in the …

Feb 10, 2025
CVE-2025-24032

PAM-PKCS#11 is a Linux-PAM login module that allows a X.509 certificate based user login. Prior to version 0.6.13, if cert_policy is set to none (the …

Feb 10, 2025
CVE-2025-24031

PAM-PKCS#11 is a Linux-PAM login module that allows a X.509 certificate based user login. In versions 0.6.12 and prior, the pam_pkcs11 module segfaults when a …

Feb 10, 2025
CVE-2025-21693
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: mm: zswap: properly synchronize freeing resources during CPU hotunplug In zswap_compress() and zswap_decompress(), the per-CPU …

Feb 10, 2025
CVE-2025-21692
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: net: sched: fix ets qdisc OOB Indexing Haowei Yan <[email protected]> found that ets_class_from_arg() can index …

Feb 10, 2025
CVE-2025-21691
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: cachestat: fix page cache statistics permission checking When the 'cachestat()' system call was added in …

Feb 10, 2025
CVE-2025-21690
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: scsi: storvsc: Ratelimit warning logs to prevent VM denial of service If there's a persistent …

Feb 10, 2025
CVE-2025-21689
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: USB: serial: quatech2: fix null-ptr-deref in qt2_process_read_urb() This patch addresses a null-ptr-deref in qt2_process_read_urb() due …

Feb 10, 2025
CVE-2025-21688
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/v3d: Assign job pointer to NULL before signaling the fence In commit e4b5ccd392b9 ("drm/v3d: Ensure …

Feb 10, 2025
CVE-2025-21687
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: vfio/platform: check the bounds of read/write syscalls count and offset are passed from user space …

Feb 10, 2025
CVE-2025-21686

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Feb 10, 2025
CVE-2024-57950
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Initialize denominator defaults to 1 [WHAT & HOW] Variables, used as denominators and maybe …

Feb 10, 2025
CVE-2024-12243
5.3 MEDIUM

A flaw was found in GnuTLS, which relies on libtasn1 for ASN.1 data processing. Due to an inefficient algorithm in libtasn1, decoding certain DER-encoded certificate …

Feb 10, 2025
CVE-2024-12133
5.3 MEDIUM

A flaw in libtasn1 causes inefficient handling of specific certificate data. When processing a large number of elements in a certificate, libtasn1 takes much longer …

Feb 10, 2025
CVE-2024-11831
5.4 MEDIUM

A flaw was found in npm-serialize-javascript. The vulnerability occurs because the serialize-javascript module does not properly sanitize certain inputs, such as regex or other JavaScript …

Feb 10, 2025
CVE-2025-1149
3.1 LOW

A vulnerability was found in GNU Binutils 2.43. It has been classified as problematic. This affects the function xstrdup of the file libiberty/xmalloc.c of the …

Feb 10, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.